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Executive Summary 


The Student Privacy Policy Office (SPPO) at the U.S. Department of Education (Department) is 
performing a four-year review of a sample of the websites of |,504 local education agencies (LEAs) to 
identify whether and how these websites include information about student privacy. In each year of the 
study, SPPO is reviewing a nationally representative sample of 376 LEA websites, focusing on whether 
the LEAs included key student privacy documents and information about the Family Educational Rights 
and Privacy Act (FERPA) and the Protection of Pupil Rights Amendment (PPRA) on the LEA website, as 
opposed to on individual school, board of education, or other websites. This report includes the first 
two years of research findings. 


Combined two-year findings: 
e 54 percent of LEAs reviewed posted on their websites the LEA’s Annual Notice under FERPA, 


e 52 percent of LEAs posted on their websites the LEA’s policy under the Directory Information 
exception under FERPA, and 


e 29 percent of LEAs posted on their website the LEA’s policy under PPRA. 


For these three key privacy documents that are posted on the LEA websites, fewer than twenty percent 
are listed as primary website content. In more than fifty percent of the cases, the documents are 
included as part of the student handbook, which may be a Portable Document Format (PDF) or other 
type of document linked from the LEA webpage. 


For the websites reviewed, 12 percent of LEA websites have navigation menus that include a section 
indicating where to find data practices and student privacy information. Moreover, only 7 percent of 
LEA websites include the LEA contact information if parents have questions about data sharing and 
student privacy. 
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Background 


This study is derived from Strategic Objective 3.2, Performance Measure 3.2c of the U.S. Department of 
Education Strategic Plan for Fiscal Years 2018-2022. To inform the Department’s review of this objective, 
SPPO and its Privacy Technical Assistance Center (PTAC) are studying LEA practices for providing 
information on data sharing and student privacy on their websites. SPPO is responsible for administering 
FERPA and PPRA, and providing guidance and best practices on student privacy to the education 
community. 


SPPO recommends as a transparency best practice that LEAs post their FERPA and PPRA student 
privacy-related information on their websites so that information is easily available to parents and the 
community. FERPA does not require that LEAs post their annual FERPA notice on their websites, but 
the law specifically requires LEAs to provide notice annually to parents of students and eligible students 
of their rights under FERPA “by any means that are reasonably likely to inform the parents or eligible 
students of their rights.” See 34 CFR § 99.7. With the increased utilization of LEA websites for the 
timely dissemination of information to the school community, SPPO believes that posting an appropriate 
notice on the LEA website is an effective manner of meeting FERPA’s Annual Notice requirement. 


Sample Selection 


In order to complete the review, a sampling plan was developed to determine which LEAs would be 
reviewed across four years of data collection (fiscal years 2019, 2020, 2021, and 2022). A single sample 
of 1,504 LEAs was selected at the outset of the study, and randomly divided into four groups of 376 
LEAs that would be reviewed across the four data collection years to create a nationally representative 
sample for each year. In addition, a replacement sample of 100 LEAs was selected that may be used if 
any original sample LEAs cannot be included at the time of data collection (for example, if the LEA 
closed, or if the LEA’s website is inactive). 


In each year of the study, 376 LEA websites, a nationally representative sample, were reviewed to 
evaluate transparency practices with respect to LEAs’ use of student data. The sample was selected to 
represent school districts of different size and socioeconomic status across different geographic regions. 
The LEA website review focused on determining whether key privacy-related documents or information 
were available on the LEA district website as opposed to on the websites of the board of education or 
individual schools. 


Results 


This report combines data from the samples from years | and 2. We found that although 54 percent of 
LEAs reviewed have the FERPA Annual Notice posted on the website, only 12 percent of LEA websites 
have navigation menus that include a section indicating where to find data practices and student privacy 
information. Moreover, 93 percent of LEA websites do not include contact information for a staff 
member dedicated to data sharing and student privacy. 
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Topic: Annual Notice 


e 54 percent of LEAs have the FERPA Annual Notice on the LEA website. 


Topic: Annual Notice 


54% 


46% 


Yes No 


Does the LEA post its annual notice on the website? 


e When the FERPA Annual Notice is on the LEA’s website, 70 percent of the time the notice is the 
Department’s model notice or a minor variant of that. 


e For 30 percent of LEAs that include the FERPA Annual Notice on the LEA’s website, the notice is 
customized by the LEA. 


Characteristics of Custom Notice Percent LEAs Yes 


Does the custom notice include the right to inspect and review students’ 95% 
education records? 


Does the custom notice include the right to seek to amend those 79% 
records? 
Does the custom notice include the right to consent to disclosure of 64% 


Personally Identifiable Information from those records (unless an 
exception applies)? 


Does the custom notice include the right to file a complaint with the 56% 
Department regarding an alleged FERPA violation? 


Does the custom notice include the procedure for exercising the right to 56% 
inspect and review education records? 


Does the custom notice include the procedure for requesting 43% 
amendment of those records? 
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Does the custom notice include the district’s criteria for determining 29% 
who constitutes a “school official?” 


Does the custom notice include the district’s criteria for determining 35% 
what constitutes a “legitimate educational interest?” 


Does the LEA disclose that it routinely releases students’ education 79% 
records to other schools in which the student seeks or intends to enroll? 


e For only |8 percent of LEAs, the FERPA Annual Notice is posted as primary website content, 
meaning the content is visible on the LEA main website or available from a dropdown menu without 
going to a PDF or an external website not maintained by the LEA. 


e For 56 percent of LEAs with the FERPA Annual Notice available, it is included in the student 
handbook. In most of these cases, the handbook is a PDF that requires the user to search through 
the document to find the information. For 34 percent of LEAs that have the Annual Notice available, 
the notice is included in a document other than or in addition to the student handbook. 


Examples of Document Types Displaying FERPA Annual Notices Besides Student 
Handbooks 


Annual Notices 


Annual Parent and Student Rights Notification 


Student Records Notice 


Code of Conduct 


Student Data Privacy and Security Policy 


FERPA Notices 


Parent Rights Under FERPA 


Parents Bill of Rights 


e 73 percent of LEAs indicate when the Annual Notification was last updated. However, in many 
cases, the date of update pertains to the entire student handbook, not the specific policy. 
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Topic: Directory Information 


e 52 percent of LEAs have the Directory Information (Dl) policy on the LEA website. 


Topic: Directory Information 
52% 


48% 


Yes No 


Does the LEA post its directory information on the website? 


e When the LEA DI policy is on the website, 52 percent of the time it is the Department’s model 
notice or a variant of that. 


e For 48 percent of LEAs, the DI policy is customized by the LEA. 


Characteristics of Customized DI Policy Percent LEAs Yes 


Does the customized policy include the types of Personally Identifiable 86% 
Information that the district or school has designated as directory 
information? 


Does the customized policy include an explanation of the right of parents 96% 
and eligible students to request that the information about the student 
not be disclosed as directory information? 


Does the customized policy include a specified period of time within 48% 
which a parent or eligible student may notify the school or LEA in writing 
that they do not want any or all of the information disclosed as directory 
information? 


e For 42 percent of LEAs with the DI policy on their website, the DI policy is a limited DI. A limited 
DI might allow limited disclosure of directory information to third parties for legitimate education 
purposes, while disallowing the disclosure of this same information to third parties for purposes 
such as marketing. 
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Characteristics of DI Policy Percent LEAs Yes 
Does the LEA DI policy include Student ID? 10% 
Does the LEA DI policy specify that student ID, by itself, cannot be used 95% 


to gain access to education records except when used in conjunction 
with one or more factors that authenticate the user’s identity (for 
example, a password)? 


Does the LEA DI policy include photo/video likenesses? 61% 


Does the LEA DI policy have a separate video and photo consent policy 18% 
(for example, for use on social media or in a newspaper)? 


Does the DI policy include disclosure to military recruiters? 58% 
Is there a separate notice for disclosure to military recruiters? 19% 
Does the LEA provide a "menu" approach allowing parents to opt in or 23% 


out of specific disclosures? (Note details in comments.) 


e For 18 percent of LEAs, directory information is posted as primary website content, meaning the 
content is visible on the LEA main website or available from a dropdown menu without going to a 
PDF or an external website not maintained by the LEA. 


e For 53 percent of LEAs with a DI policy available, it is included in the student handbook. In most of 
these cases, the handbook is a PDF that requires the user to search through the document to find 
the information. For 38 percent of LEAs with a DI policy available, the notice is included within or as 
part of another document. 


Examples of Document Types Displaying the LEA DI Policy Besides Student Handbooks 


Student Directory Information Notification 


Student Records Policy 


FERPA Notices 


Annual Notices 


Public Notice Policy 


Student Code of Conduct 


Student Data Privacy and Security 


e 73 percent of LEAs indicate when the DI policy was last updated. However, in many cases, the date 
of update pertains to the entire student handbook, not the specific policy. 
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Topic: PPRA 


e 29 percent of LEAs have the PPRA Notice on the LEA website. 


Topic: PPRA 
71% 


Yes No 


Does the LEA post its PPRA policy on its website? 


e When the PPRA Notice is on the LEA’s website, 84 percent of the time it is the Department's 
model notice or a variant of that. 


e For 16 percent of LEAs, the PPRA Notice is customized by the LEA. 


Characteristics of Custom PPRA Notice Percent LEAs Yes 


Does the LEA PPRA Notice indicate it is provided to parents at 64% 
least annually? 


Is there an indication when the LEA PPRA Notice was last updated? 78% 


e For 14 percent of the LEAs, the PPRA Notice is posted as primary content, meaning the content is 
visible on the LEA main website or available from a dropdown menu without going to a PDF or an 
external website not maintained by the LEA. 


e For 60 percent of the LEAs with a PPRA notice available, it is included in the student handbook. In 
most of these cases, the handbook is a PDF that requires the user to search through the document 
to find the information. For 29 percent of LEAs with a PPRA notice available, it is included within or 
as part of another document. 
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Examples of Document Types Displaying LEA PPRA Notices Besides Student 
Handbooks 


Parent/Guardian Rights 
Behavioral Code Book 


FERPA Notices 


Annual Notices 


PPRA Notice Document 


Notification of Rights Under the Protection of Pupil Rights Amendment (PPRA) 


Student Code of Conduct 
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Topic: Data Inventory 


e Only 4 percent of the LEAs have a data inventory listing information collected by the LEA from or 
about its student available on their websites. 


Topic: Data Inventory Listing 
Information Collected by the LEA from 
or about its Students 


96% 


4% 


Yes No 


Does the LEA website have a data inventory listing information 
collected by the LEA from or about its students? 
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Topic: Data Security 


e 37 percent of LEAs have a description of information technology (IT) security and data protection 
policies on the LEA website. 


Topic: Data Security 
63% 


Yes No 


Does the LEA website have a description of IT security and 
data protection policies? 


Characteristics of Data Security Policies Percent LEAs Yes 


Does the LEA website have a description of policies or procedures 4% 
specifically for paper records? 


Does the LEA website have a description of policies or procedures 48% 
specifically for digital information? 


Does the LEA website have a description of policies or procedures 31% 
specifically for access to student personally identifiable information? 


Does the LEA website have a description of policies or procedures 26% 
specifically for use of student personally identifiable information? 


Does the LEA website describe how student records are retained 2% 
(for example, identifiable, minimized or redacted, de-identified)? 


Does the LEA website have policies describing how the LEA de- 1% 
identifies student personally identifiable information before 
publishing or disclosing to third parties? 
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Topic: Data Sharing 


e 37 percent of LEAs have a description of data sharing policies posted on their LEA websites. 


Topic: Data Sharing 
63% 


37% 


Yes No 


Does the LEA website have a description of any data 
sharing policies? 


Characteristics of Data Sharing Policies Percent LEAs Yes 


Does the LEA website indicate whether student personally 27% 
identifiable information is shared with third parties? 


Does the LEA website indicate whether personally identifiable 3% 
information is shared with external researchers? 

If yes, are written agreements with researchers available? 13% 
If yes, are study results available? 9% 
If yes, are any resulting changes to curriculum, policies, or programs 0% 
listed? 

Does the LEA website indicate if personally identifiable information 4% 


is shared with education technology companies? 


Does the LEA website indicate the purpose for sharing personally 74% 
identifiable information with education technology companies? 
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Does the LEA website have posted online contracts or written 49% 
agreements with companies or organizations to whom the LEA 

discloses students’ personally identifiable information? 

Does the LEA website have a list of approved online services or 22% 
apps used in classrooms? 

Does the LEA website describe a policy or process for vetting or 14% 
approving apps? 

Does the LEA website list any differentiation between required and 3% 
optional apps? 

Are links to non-contracted apps’ terms of service posted? 23% 
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Topic: Communications 


e 7 percent of LEA websites include contact information for a staff member dedicated to data sharing 
and student privacy. 


Topic: Communications 


93% 


7% 


Yes 


e 12 percent of LEA websites have navigation menus that include a section indicating where to find 
data practices and student privacy information. 


e 85 percent of LEA websites have a general search tool. 


Search Tool Term Results Include Privacy-Related 
Information 
FERPA 43% 
Annual Notification 23% 
Student Privacy 45% 
Directory Information 29% 
PPRA 17% 
Technology 15% 
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Applications 4% 
Apps 10% 
Privacy 47% 
Confidentiality 29% 
Disclosure 31% 
Security 20% 


e 3 percent of LEA websites include a glossary of privacy-related terms. 


e 66 percent of LEA websites have language translations, meaning the website can be viewed ina 


language other than English. 


Language Translation 


Percent LEAs Yes 


All privacy related documents available in language translations 


23% 


Key privacy related documents available in language translations 
(Annual Notice, Directory Information Policy, PPRA Notice) 


Example documents included 


37% 


Annual Notice, Directory 
Information Policy, PPRA 
Notice, privacy frequently 
asked questions, student 
handbook, Parent Bill of Rights, 
or entire website is available in 
language translations 


Example languages available 
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Spanish, Korean, Russian, 
Vietnamese, Arabic, Chinese, 
French, Tagalog, Italian, 
German, Hindi, Japanese, 
Somali, Portuguese, Creole 


(In many cases, the sites use 
Google Translate, which 
provides translations in many 
languages) 
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Plans for Years 3 and 4 Samples 


Samples from Years 3 and 4 will be subject to the same procedures and sampling tool to collect data, 
analyze the data, and share the results with the LEAs that are examined. Each year, SPPO will produce a 
high-level summary of the findings from that year. After each review, SPPO staff and contractors will 
provide outreach to the LEAs in that year’s sample. 


One hundred percent of these reviews will be completed by the end of the fifth year of the study, by 
September 30, 2022. After completion of all reviews, SPPO will produce a final report summarizing the 
findings and making general recommendations for all LEAs. 
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Additional Resources 


e FERPA Model Notification of Rights for Elementary & Secondary Schools, 
https://studentprivacy.ed.gov/node/490 


e Model Notice for Directory Information, https://studentprivacy.ed.gov/node/428 


e Model Notice for Directory Information En Espanol, https://studentprivacy.ed.gov/node/489 


e PPRA Model General Notice of Rights, https://studentprivacy.ed.gov/node/49 | 


e Transparency Best Practices, https://studentprivacy.ed.gov/resources/transparency-best-practices 


e US. Department of Education Strategic Plan for Fiscal Years 201 8-2022, 
https://www72.ed.gov/about/reports/strat/plan20 |8-22/strategic-plan.pdf 


About the Student Privacy Policy Office 


The U.S. Department of Education’s Student Privacy Policy Office (SPPO) is responsible for the 
administration and enforcement of federal laws relating to the privacy of students’ education records, 
and for the provision of technical assistance on student privacy issues for the broader education 
community. For more information about the office or to access student privacy guidance and best 
practices, please visit SPPO's webpage at https://studentprivacy.ed.gov/. 
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